Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

zzcms — Vulnerabilities & Security Advisories 20

All 20 CVE vulnerabilities found in zzcms, with AI-generated Chinese analysis, references, and POCs.

This page documents known security vulnerabilities associated with the zzcms content management system, categorized by weakness type and indexed by vendor advisories. It aggregates data regarding diverse security flaws including cross-site scripting, SQL injection, and remote code execution vectors identified in this specific software ecosystem. The collection covers vulnerability reports and updates spanning from the product’s early releases through recent patches, ensuring a comprehensive historical record of security issues. By consulting this resource, users can track a vendor's security advisories to monitor the lifecycle of reported issues, understand the technical nature and impact of specific weakness classes within the context of web content management, or look up a product's vulnerability history to assess past exposure and remediation efforts. This consolidated view aids security professionals, developers, and system administrators in evaluating the overall security posture of zzcms instances. The data presented here is strictly informational, intended to support risk assessment and patch management decisions without implying any endorsement or warranty. Readers are encouraged to cross-reference this information with official vendor patches and independent security analyses for the most current mitigation strategies. The scope includes both publicly disclosed vulnerabilities and those identified through community research, providing a holistic picture of the threat landscape surrounding this application.

Vendor: zzcms

CVE ID Title CVSS Severity Published
CVE-2025-14837 ZZCMS Backend Website Settings siteconfig.php stripfxg code injection CWE-94 4.7 Medium 2025-12-17
CVE-2025-14836 ZZCMS User Data Storage user_save.php cleartext storage in file CWE-313 2.7 Low 2025-12-17
CVE-2025-13171 ZZCMS wangkan_list.php sql injection CWE-89 6.3 Medium 2025-11-14
CVE-2025-1949 ZZCMS URL register_nodb.php cross site scripting CWE-79 4.3 Medium 2025-03-04
CVE-2025-0565 ZZCMS index.php sql injection CWE-89 7.3 High 2025-01-19
CVE-2024-11242 ZZCMS Keyword Filtering ad_list.php sql injection CWE-89 4.7 Medium 2024-11-15
CVE-2024-11130 ZZCMS msg.php cross site scripting CWE-79 2.4 Low 2024-11-12
CVE-2024-10293 ZZCMS functions.php Ebak_SetGotoPak unrestricted upload CWE-434 6.3 Medium 2024-10-23
CVE-2024-10292 ZZCMS ChangeTable.php unrestricted upload CWE-434 6.3 Medium 2024-10-23
CVE-2024-10291 ZZCMS phome.php Ebak_DotranExecutSQL sql injection CWE-89 6.3 Medium 2024-10-23
CVE-2024-10290 ZZCMS inc.php information disclosure CWE-200 5.3 Medium 2024-10-23
CVE-2024-7927 ZZCMS class.php path traversal CWE-22 7.3 High 2024-08-19
CVE-2024-7926 ZZCMS about_edit.php path traversal CWE-22 7.3 High 2024-08-19
CVE-2024-7925 ZZCMS eginfo.php information disclosure CWE-200 4.3 Medium 2024-08-19
CVE-2024-7924 ZZCMS list.php path traversal CWE-22 5.3 Medium 2024-08-19
CVE-2019-1010153 ZZCMS SQL注入漏洞 9.8 - 2019-07-23
CVE-2019-1010152 ZZCMS 输入验证错误漏洞 9.8 - 2019-07-23
CVE-2019-1010150 ZZCMS 输入验证错误漏洞 9.8 - 2019-07-23
CVE-2019-1010149 ZZCMS 输入验证错误漏洞 9.8 - 2019-07-23
CVE-2019-1010148 ZZCMS SQL注入漏洞 9.8 - 2019-07-23

All 20 known CVE vulnerabilities affecting zzcms with full Chinese analysis, references, and POCs where available.